Exchange Administrative center external access

One of the concerns that has been raised is the ability to access Exchange Control panel for Exchange 2010 and Exchange Administrative Center for 2013/2016 externally. Is there a way to prevent external access maybe by limiting the IP ranges that could access it to internal IP ranges only.

For information, the only way to block ECP without resorting to an application aware firewall is to create a second version of the ECP site that is only accessible using an Internal IP address that is assigned as a secondary IP on the Exchange server. Todd's second link explains the process, but be aware that it is a fairly involved process.

Featured Post

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center.
Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center.
Navigate to the Servers >> Data…